plugin

Conveythis Translate Vulnerabilities

10 known security issues reported for the Conveythis Translate WordPress plugin. Most recent disclosed Feb 20, 2026.

1 high 4 medium

Running Conveythis Translate on your site? Check whether your installed version is affected.

Scan your site free

Translate WordPress Websites Globally with ConveyThis Translate [conveythis-translate] <= 269.5 (unfixed)

unknown

[en] Missing Authorization vulnerability in ConveyThis ConveyThis conveythis-translate allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ConveyThis: from n/a through <= 269.5.

Affected:
up to 269.5
Fix:
No patched version reported
Disclosed:
Feb 20, 2026

CVE-2025-68021 on NVD →

ConveyThis <= 270.4 - Missing Authorization

medium

The ConveyThis plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 270.4. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 270.4
Fixed in:
270.5
Disclosed:
Jan 27, 2026

CVE-2025-68021 on NVD →

Translate WordPress Websites Globally with ConveyThis Translate [conveythis-translate] <= 268.10 (unfixed)

unknown

[en] Missing Authorization vulnerability in ConveyThis ConveyThis conveythis-translate allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ConveyThis: from n/a through <= 268.10.

Affected:
up to 268.10
Fix:
No patched version reported
Disclosed:
Dec 9, 2025

CVE-2025-62152 on NVD →

ConveyThis <= 269.2 - Missing Authorization

medium

The ConveyThis plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 269.2. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 269.2
Fixed in:
269.3
Disclosed:
Nov 29, 2025

CVE-2025-62152 on NVD →

Language Translate Widget for WordPress – ConveyThis <= 269.1 - Authenticated (Administrator+) PHP Object Injection

medium

The Language Translate Widget for WordPress – ConveyThis plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 269.1 via deserialization of untrusted input. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No kn...

CVSS:
6.6
Affected:
up to 269.1
Fixed in:
269.2
Disclosed:
Sep 22, 2025

CVE-2025-57919 on NVD →

Translate WordPress Websites Globally with ConveyThis Translate [conveythis-translate] < 235

unknown

[en] Missing Authorization vulnerability in ConveyThis Translate Team Language Translate Widget for WordPress – ConveyThis allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Language Translate Widget for WordPress – ConveyThis: from n/a through 234.

Affected:
up to 235
Fixed in:
235
Disclosed:
Nov 1, 2024

CVE-2024-38792 on NVD →

Language Translate Widget for WordPress – ConveyThis <= 234 - Missing Authorization to Limited Option Update

medium

The Language Translate Widget for WordPress – ConveyThis plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check in the /app/connect/ConveyThisStart.php file in versions up to, and including, 234. This makes it possible for unauthenticated attackers to update the api_ke...

CVSS:
5.3
Affected:
up to 234
Fixed in:
235
Disclosed:
Jul 22, 2024

CVE-2024-38792 on NVD →

Translate WordPress Websites Globally with ConveyThis Translate [conveythis-translate] < 224

unknown

[en] The Language Translate Widget for WordPress – ConveyThis plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'api_key’ parameter in all versions up to, and including, 223 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject...

Affected:
up to 224
Fixed in:
224
Disclosed:
Apr 11, 2024

CVE-2023-6811 on NVD →

Language Translate Widget for WordPress – ConveyThis <= 223 - Unauthenticated Stored Cross-Site Scripting via api_key

high

The Language Translate Widget for WordPress – ConveyThis plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'api_key’ parameter in all versions up to, and including, 223 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbi...

CVSS:
7.2
Affected:
up to 223
Fixed in:
224
Disclosed:
Apr 10, 2024

CVE-2023-6811 on NVD →

Translate WordPress Websites Globally with ConveyThis Translate [conveythis-translate] <= 266 (unfixed)

unknown
Affected:
up to 266
Fix:
No patched version reported

CVE-2025-57919 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database